LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Newbie
User Name
Password
Linux - Newbie This Linux forum is for members that are new to Linux.
Just starting out and have a question? If it is not in the man pages or the how-to's this is the place!

Notices


Reply
  Search this Thread
Old 06-06-2008, 04:53 AM   #1
i_nomad
Member
 
Registered: Mar 2008
Distribution: RedHatES4
Posts: 144

Rep: Reputation: 15
Logwatch detail


Hi Guys

Since I have implemented TLS on the postfix the logwatch reports are showing the complete certificate exchange process. I just want the report to show relay denied but not the TLS exchange.

I am seeing hundreds of messages like:
"
Read from 552AC47D30 [552AC5151B] (59 bytes => -1 (0xFFFFFFFFFFFFFFFF)) SSL_accept:error in SSLv3 read client hello B SSL_accept:error in SSLv3 read client hello B read from 552AC47D30 [552AC5151B] (59 bytes => 59 (0x3B)) 0000 48 46 9d 6d f7 43 3a 29|70 57 3e 32 ff 53 21 ab HF.m.C pW>2.S!. 0010 0e 13 85 40 c8 ce 97 62|6c b6 4f a9 51 66 c2 a1 ...@...b l.O.Qf.. 0020 00 00 16 00 04 00 05 00|0a 00 09 00 64 00 62 00 ........ ....d.b.
0030 03 00 06 00 13 00 12 00|63 01 ........ c.
003a - <SPACES/NULLS>
SSL_accept:SSLv3 read client hello B
SSL_accept:SSLv3 write server hello A
SSL_accept:SSLv3 write certificate A
SSL_accept:SSLv3 write server done A
write to 552AC47D30 [552AC5F6D0] (1129 bytes => 1129 (0x469)) 0000 16 03 01 00 4a 02 00 00|46 03 01 48 46 9d 6d 6e ....J... F..HF.mn 0010 22 c2 14 3e 8f 27 1e 78|b0 d6 67 30 bf 59 b6 ff "..>.'.x ..g0.Y.. 0020 e5 ee 82 94 d7 cc ac 00|00 00 00 20 ef 01 2c 9f ........ ... ..,. 0030 2d af 5c 64 c7 c4 f2 a3|c5 e5 30 33 ee 0a 18 7c -.\d.... ..03...| 0040 1c 77 b3 86 18 79 3c f7|e7 64 a2 9c 00 04 00 16 .w...y<. .d...... 0050 03 01 04 0c 0b 00 04 08|00 04 05 00 04 02 30 82 ........ ......0. 0060 03 fe 30 82 03 67 a0 03|02 01 02 02 01 01 30 0d ..0..g.. ......0. 0070 06 09 2a 86 48 86 f7 0d|01 01 04 05 00 30 81 a8 ..*.H... .....0.. 0080 31 0b 30 09 06 03 55 04|06 13 02 47 42 31 0f 30 1.0...U. ...
...
...and

SSL_accept:SSLv3 flush data
initializing the server-side TLS engine
initializing the server-side TLS engine
initializing the server-side TLS engine
initializing the server-side TLS engine
initializing the server-side TLS engine
initializing the server-side TLS engine
initializing the server-side TLS engine
initializing the server-side TLS engine
initializing the server-side TLS engine
initializing the server-side TLS engine"

How do I get rid of this. I have tried altering the logwatch detail down to med and low but this does not impact.

I do not mind /var/log/maillog showing detail but would like to limit this also.

I would appreciate any help.

Regards
 
Old 06-06-2008, 04:59 AM   #2
i_nomad
Member
 
Registered: Mar 2008
Distribution: RedHatES4
Posts: 144

Original Poster
Rep: Reputation: 15
Sorry I have just found the postfix log level. I will try to adjust this.

Regards
 
Old 06-06-2008, 03:45 PM   #3
Mr. C.
Senior Member
 
Registered: Jun 2008
Posts: 2,529

Rep: Reputation: 63
or update of the postfix filter to the latest version.

MrC
 
Old 06-06-2008, 03:46 PM   #4
Mr. C.
Senior Member
 
Registered: Jun 2008
Posts: 2,529

Rep: Reputation: 63
... available at http://www.mikecappella.com/logwatch

MrC
[ sorry - the forum required I post once before I could post the URL ]
 
Old 06-09-2008, 09:41 AM   #5
i_nomad
Member
 
Registered: Mar 2008
Distribution: RedHatES4
Posts: 144

Original Poster
Rep: Reputation: 15
I turned the smtpd_tls_loglevel = 0 in postfix. That has removed alot of the gumph.

Regards
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Question about suid detail... redbot Linux - Security 6 10-01-2007 09:59 AM
Need any detail documentation of PFIL_HOOK ahm_irf Programming 0 05-01-2007 09:55 AM
Detail of Automount process Pr_009 Fedora 1 02-27-2006 04:59 AM
Its in the detail! legin Fedora 1 01-07-2005 07:37 AM
Detail Logging Lucasite Linux - Security 1 03-06-2004 06:10 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Newbie

All times are GMT -5. The time now is 12:33 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration